
Chapter 24 AAA
GS2200-24/24P User’s Guide
210
accounts configured on the Switch itself. The Switch can also use an external
authentication server to authenticate a large number of users
Authorization is the process of determining what a user is allowed to do. Different
user accounts may have higher or lower privilege levels associated with them. For
example, user A may have the right to create new login accounts on the Switch
but user B cannot. The Switch can authorize users based on user accounts
configured on the Switch itself or it can use an external server to authorize a large
number of users.
Local User Accounts
By storing user profiles locally on the Switch, your Switch is able to authenticate
and authorize users without interacting with a network AAA server. However, there
is a limit on the number of users you may authenticate in this way (See
RADIUS and
RADIUS and are security protocols used to authenticate users by means
of an external server instead of (or in addition to) an internal device user database
that is limited to the memory capacity of the device. In essence, RADIUS and
authentication both allow you to validate an unlimited number of users
from a central location.
The following table describes some key differences between RADIUS and
.
24.2 AAA Screens
The AAA screens allow you to enable authentication and authorization or both of
them on the Switch. First, configure your authentication server settings (RADIUS,
or both) and then set up the authentication priority, activate
authorization.
Table 59
RADIUS vs.
RADIUS
Transport
Protocol
UDP (User Datagram Protocol)
TCP (Transmission Control Protocol)
Encryption
Encrypts the password sent for
authentication.
All communication between the client
(the Switch) and the TACACS server
is encrypted.
Summary of Contents for GS2200-24P Series
Page 2: ......
Page 8: ...Safety Warnings GS2200 24 User s Guide 8...
Page 22: ...22...
Page 28: ...Chapter 1 Getting to Know Your Switch GS2200 24 24P User s Guide 28...
Page 32: ...Chapter 2 Hardware Installation and Connection GS2200 24 24P User s Guide 32...
Page 40: ...Chapter 3 Hardware Panels GS2200 24 24P User s Guide 40...
Page 42: ...42...
Page 52: ...Chapter 4 The Web Configurator GS2200 24 24P User s Guide 52...
Page 90: ...Chapter 8 Basic Setting GS2200 24 24P User s Guide 90...
Page 92: ...92...
Page 110: ...Chapter 9 VLAN GS2200 24 24P User s Guide 110 Figure 58 Port Based VLAN Setup Port Isolation...
Page 116: ...Chapter 10 Static MAC Forward Setup GS2200 24 24P User s Guide 116...
Page 144: ...Chapter 13 Spanning Tree Protocol GS2200 24 24P User s Guide 144...
Page 148: ...Chapter 14 Bandwidth Control GS2200 24 24P User s Guide 148...
Page 152: ...Chapter 15 Broadcast Storm Control GS2200 24 24P User s Guide 152...
Page 156: ...Chapter 16 Mirroring GS2200 24 24P User s Guide 156...
Page 166: ...Chapter 17 Link Aggregation GS2200 24 24P User s Guide 166...
Page 174: ...Chapter 19 Port Security GS2200 24 24P User s Guide 174...
Page 186: ...Chapter 21 Policy Rule GS2200 24 24P User s Guide 186...
Page 208: ...Chapter 23 Multicast GS2200 24 24P User s Guide 208...
Page 246: ...Chapter 25 IP Source Guard GS2200 24 24P User s Guide 246...
Page 255: ...255 PART IV IP Application Static Route 257 Differentiated Services 261 DHCP 265...
Page 256: ...256...
Page 260: ...Chapter 28 Static Route GS2200 24 24P User s Guide 260...
Page 274: ...274...
Page 304: ...Chapter 32 Access Control GS2200 24 24P User s Guide 304...
Page 310: ...Chapter 34 Syslog GS2200 24 24P User s Guide 310...
Page 318: ...Chapter 35 Cluster Management GS2200 24 24P User s Guide 318...
Page 322: ...Chapter 36 MAC Table GS2200 24 24P User s Guide 322...
Page 328: ...328...
Page 340: ...Chapter 40 Product Specifications GS2200 24 24P User s Guide 340...
Page 342: ...342...
Page 344: ...Appendix A Changing a Fuse GS2200 24 24P User s Guide 344...
Page 352: ...Appendix C Legal Information GS2200 24 24P User s Guide 352...